Threagile | DefectDojo Documentation
Threagile
File Types
DefectDojo parser accepts a .json file.
JSON reports are created from the Threagile tool (default name risks.json) using the following command:
docker run --rm -it -v "$(pwd)":/app/work threagile/threagile -verbose -model /app/work/threagile.yaml -output /app/work
Acceptable JSON Format
Parser expects an array of findings. All properties are strings. Required fields are the following
- “category”
- “title”
- “severity”
- “synthetic_id”
- “exploitation_impact”
category field is used to set both the title of the Finding as well as the CWE.
most_relevant_technical_asset field is used to determine the component.
[
{
"category": "unguarded-direct-datastore-access",
"risk_status": "unchecked",
"severity": "elevated",
"exploitation_likelihood": "likely",
"exploitation_impact": "medium",
"title": "<b>Unguarded Direct Datastore Access</b> of <b>PoliciesRegoStorage</b> by <b>Energon</b> via <b>EnergonToPolicyRegoFileStorage</b>",
"synthetic_id": "unguarded-direct-datastore-access@energon-ta>energontopolicyregofilestorage@energon-ta@policies-rego-storage-ta",
"most_relevant_data_asset": "",
"most_relevant_technical_asset": "policies-rego-storage-ta",
"most_relevant_trust_boundary": "",
"most_relevant_shared_runtime": "",
"most_relevant_communication_link": "energon-ta>energontopolicyregofilestorage",
"data_breach_probability": "improbable",
"data_breach_technical_assets": [
"policies-rego-storage-ta"
]
},
{
"category": "unguarded-direct-datastore-access",
"risk_status": "in-discussion",
"severity": "elevated",
"exploitation_likelihood": "likely",
"exploitation_impact": "medium",
"title": "<b>Unguarded Direct Datastore Access</b> of <b>PoliciesRegoStorage</b> by <b>IAMSidecar</b> via <b>IAMBachendAPIPoliciesRegoFileStorage</b>",
"synthetic_id": "unguarded-direct-datastore-access@iam-sidecar-ta>iambachendapipoliciesregofilestorage@iam-sidecar-ta@policies-rego-storage-ta",
"most_relevant_data_asset": "",
"most_relevant_technical_asset": "policies-rego-storage-ta",
"most_relevant_trust_boundary": "",
"most_relevant_shared_runtime": "",
"most_relevant_communication_link": "iam-sidecar-ta>iambachendapipoliciesregofilestorage",
"data_breach_probability": "improbable",
"data_breach_technical_assets": [
"policies-rego-storage-ta"
]
},
{
"category": "unguarded-direct-datastore-access",
"risk_status": "accepted",
"severity": "elevated",
"exploitation_likelihood": "likely",
"exploitation_impact": "medium",
"title": "<b>Unguarded Direct Datastore Access</b> of <b>PoliciesRegoStorage</b> by <b>IDMSidecar</b> via <b>IAMSidecarPoliciesRegoFileStorage</b>",
"synthetic_id": "unguarded-direct-datastore-access@idm-sidecar-ta>iamsidecarpoliciesregofilestorage@idm-sidecar-ta@policies-rego-storage-ta",
"most_relevant_data_asset": "",
"most_relevant_technical_asset": "policies-rego-storage-ta",
"most_relevant_trust_boundary": "",
"most_relevant_shared_runtime": "",
"most_relevant_communication_link": "idm-sidecar-ta>iamsidecarpoliciesregofilestorage",
"data_breach_probability": "improbable",
"data_breach_technical_assets": [
"policies-rego-storage-ta"
]
},
...
]
Sample Scan Data
Sample Threagile scans can be found here.
Default Deduplication Hashcode Fields
By default, DefectDojo identifies duplicate Findings using these hashcode fields:
- title
- cwe
- severity